// v. SUPPORT STAGE

Security isn't a checkbox —
it's a posture.

Compliance audits don't make systems secure. Posture does. We embed as a security partner, not a vendor: we deploy Wazuh as a SIEM that actually detects, wire vulnerability management into the pipeline so CVEs get caught before deploy, harden systems as code, and document every control, runbook, and decision in your knowledge base. Your team learns to maintain the posture; Codyssey retains accountability for the architecture and the hard calls.

// IN SHORT

We build a security posture, not a binder: Wazuh SIEM tuned to your environment, vulnerability management gated in CI/CD via Dependency-Track, SonarQube, and govulncheck, CIS-aligned hardening applied as Ansible roles, and ISO 27001/NIS2 mapping produced as a byproduct of operations. Every control, rule, and runbook is transferred through your knowledge base.

The problem

Security work splits into two failure modes. The first is checkbox security — a compliance framework is adopted, controls are documented, the audit passes, and the underlying system is still wide open because nobody treated the controls as engineering. The second is alert fatigue — a SIEM is deployed with default rules, it generates thousands of alerts a day, the team ignores all of them, and the real intrusion is buried in the noise. In both cases, the customer's knowledge base is a slide deck, not a working reference.

Both failures come from treating security as a separate activity from operations, or as a vendor deliverable. We don't. Security is part of how the system is built, how it's monitored, and how it responds. The SIEM is tuned. The vulnerability scans gate the pipeline. The hardening is applied as code, and the rationale lives in your knowledge base — so your team can maintain and improve the posture, not just inherit it.

What we do

We build a security posture, not a security binder. The work spans detection, prevention, compliance, and response — and it's integrated with the rest of the lifecycle, not bolted on after. We implement it alongside your team, transfer the workflow, and enrich your knowledge base with hardening guides, tuned SIEM rules, compliance mappings, and incident-response runbooks. Codyssey keeps responsibility for the architecture and hard calls; your team owns the day-to-day execution.

A posture is two things working together: an active defender that watches and responds, and a fixed control that never gets tired, never gets distracted, and never misses. The defender tracks every probe. The wall enforces the baseline. Neither one is optional — and neither one is a document.

In the illustration above, the moving paddle is your tuned detection and response — the SIEM rules, the gated pipeline, the runbook. The static wall is the hardened baseline: controls applied as code that hold the line regardless of what the day looks like. Every probe gets intercepted or blocked. That is what "secure" looks like in operation — not a passed audit, a working game.

  • Wazuh SIEM. Host-based detection, file integrity monitoring, log analysis, and active response. We tune the rules to your environment so alerts correspond to real threats, not to default noise. The tuned rules and the reasoning behind them are documented in your knowledge base, and your team is enabled to adjust them.
  • Vulnerability management. Dependency-Track for software composition analysis, SonarQube for static analysis, and govulncheck for Go binaries. Vulnerabilities are tracked, prioritized by exploitability, and gated in CI/CD where it matters — a practice your team can maintain.
  • Compliance support. ISO 27001 and NIS2 control mapping, evidence collection, and audit readiness. We produce the artifacts an auditor asks for as a byproduct of operating the system well — not as a separate fire drill. Evidence and mappings are stored in your knowledge base, so your team can reproduce them.
  • Hardening. Baseline hardening applied as Ansible roles — CIS-aligned where it fits, risk-tuned where it doesn't. OPNsense at the perimeter where a firewall earns its place. Hardening guides and deviation tracking live in your knowledge base, and we train your team to extend them.
  • Incident response and root-cause analysis. When something breaks or breaches, we contain, investigate, and write the root-cause analysis that prevents the next one. The RCA, remediation, and response runbook go into your knowledge base. Your team owns the follow-up; Codyssey owns the hard calls. Blame is not a deliverable.
A control that isn't enforced in code is a suggestion. A SIEM that alerts on everything alerts on nothing. Security is what the system does when nobody is watching it.— Support principle, applied to every stack we harden

Deliverables

  • Security baseline — hardening roles applied as code, with deviation tracking, remediation, and an operating guide in your knowledge base
  • SIEM deployment — Wazuh deployed, rules tuned to your environment, integrated with monitoring, with tuning notes in your knowledge base
  • Vulnerability management pipeline — Dependency-Track, SonarQube, and govulncheck wired into CI/CD, with gating documented
  • Compliance documentation — ISO 27001 and NIS2 control mapping with evidence collected from operations and stored in your knowledge base
  • Hardening guides — system-level and application-level, written for the engineers who maintain them and kept in your knowledge base
  • Incident response runbook and knowledge transfer — containment, investigation, communication, RCA process, and enablement sessions so your team can own the response

Tech we use

WazuhDependency-TrackSonarQubegovulncheckOPNsenseAnsibleLinuxWireGuard

Wazuh is the open-source SIEM we standardize on — it does host-based detection, file integrity, and log analysis in one agent, and its active response can contain threats without a separate tool. Dependency-Track gives us software bill-of-materials visibility across every service, and govulncheck keeps Go binaries honest. OPNsense handles perimeter filtering where the workload justifies a dedicated firewall rather than host-level rules. Every control choice, tuning decision, and operating procedure is captured in your knowledge base as part of the transfer, so your team can maintain a security posture proven against real attack patterns with less routine overhead.

Next stage

Secure systems still decay without maintenance. We keep infrastructure current, optimized, and self-improving, and we document security context in your knowledge base so the posture survives team changes. Maintenance & Continuous Improvement →

Common questions

Is security bolted on at the end?

No — DevSecOps from day one. Wazuh runs as the SIEM, Dependency-Track and govulncheck handle vulnerability scanning, SonarQube gates code quality, and hardening is applied to every layer as code. Security is part of how the system is built, monitored, and responded to.

Do you support compliance frameworks?

Work is done with ISO 27001 and NIS2 awareness. Control mapping, evidence collection, and audit readiness are produced as a byproduct of operating the system well — for regulated environments like fintech and defense, compliance mapping is part of the deliverable, not a separate engagement.

Will the SIEM flood us with alerts?

Not the way we tune it. Default SIEM rules generate thousands of alerts a day and bury the real intrusion. We tune Wazuh to your environment so alerts correspond to real threats, and the tuned rules plus the reasoning behind them are documented in your knowledge base.

Want a posture, not a binder?

We deploy Wazuh, wire vulnerability scans into the pipeline, and harden systems as code. If your security is still a checkbox exercise, let's talk.